Solved

double encryption

Posted on 2011-09-09
7
415 Views
Last Modified: 2012-05-12
Is there any benefits in enforcing double encryption on my corproatye laptop.

Let me explain - all laptop devices come with pointsec installed - yet I sometimes have to store quite sensitive data locally on my device - could I not put something like truecrypt on and then encrypt these files when they are saved locally.

My fear is when I logon to truecrypt I essentially "unencrypt" eevrything - but I cant quite get my head around how encrypting certain files again really improves things.
0
Comment
Question by:pma111
7 Comments
 
LVL 9

Assisted Solution

by:akitsupport
akitsupport earned 100 total points
ID: 36509273
In many ways your just doubling up.  If the main solution your using is good enough why use another?

You could also end up with one item causing issues with the other as well.

0
 
LVL 3

Author Comment

by:pma111
ID: 36509350
I was wondering perhaps if I got infected by malware - as I unencrypt when I boot my machine with pointsec - the malware could see / send any documents - anything sensitive should remain encrypted "always" unless specifically needed, whereas pointsec opens "all my files" when I authenticate" - truecrypt would keep those high sensitive ones encrypted unless I manually mounted that file via authentication
0
 
LVL 9

Expert Comment

by:akitsupport
ID: 36509400
I would think as you have an encryption software your using a good anti virus though?

I'd consider using malwarebytes in conjunction with what you ahve if your really worried.

0
Use Case: Protecting a Hybrid Cloud Infrastructure

Microsoft Azure is rapidly becoming the norm in dynamic IT environments. This document describes the challenges that organizations face when protecting data in a hybrid cloud IT environment and presents a use case to demonstrate how Acronis Backup protects all data.

 
LVL 3

Author Comment

by:pma111
ID: 36509837
Yeah I guess I am overparanoid
0
 
LVL 32

Accepted Solution

by:
aleghart earned 200 total points
ID: 36512312
It's not overly paranoid.  Once you logon to the OS, your user credentials can be used by anyone with local or remote access.  This means your local files (even if encrypted by the OS), your network files, even connections to network servers & workstations...because your logon credentials are unlocked and used without challenge.

Decent password protection software offers the ability to challenge before using the credentials.  LastPass, for instance, can logon to a site or show locked info automatically, or only after a password challenge.

Same can be done for your sensitive files.  3rd-party encryption (even as simple as a ZIP file) would decrease exposure.  It wouldn't stop somebody from stealing your files if you were hacked or forced to logon to your computer.  But, you would have an amount of time you could reasonably expect some of that data to be safe.  This gives you the chance to make the data irrelevant, or at least take measures to warn others and secure other assets against the breach.

Traveling internationally, your computer is subject to seizure and search.  You may be required to logon to your computer or face detention.  Your computer can also be confiscated for later search.  (This is for the U.S. ...your country may vary.)
0
 
LVL 9

Assisted Solution

by:gtkfreak
gtkfreak earned 100 total points
ID: 36515177
Double encryption offers one more layer of protection. therefore, at times i too do that. You can also have truecrypt encryption for the whole volume, and within that one more layer of encryption on some truecrypt containers that have sensitive files. End of day, once you log into to your system, anything going across a network will be unencrypted or plaintext. Just an additional encryption layer on sensitive files.

During travel, you are required to enter a password to allow law enforcement to search your computer, but an additional encrypted container may not require you to enter that password, unless it is detected during the search. However, truecrypt does offer hidden volumes to help avoid detection. The operative word is avoid and not evade.
0
 
LVL 12

Assisted Solution

by:coredatarecovery
coredatarecovery earned 100 total points
ID: 36515228
Truecrypt is a great solution in this case
0

Featured Post

Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Using Outlook for iOS securely 2 44
Citrix 6.5 / Receiver 12.x / MAC OS 10.x 9 64
Malwarebytes keeps blocking this..... 6 35
Decrypt string by php 7 31
If you thought ransomware was bad, think again! Doxware has the potential to be even more damaging.
This article outlines the process to identify and resolve account lockout in an Active Directory environment.
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question